California Healthcare News
cahcnews.com
Articles, Jobs and Consultants for the Healthcare Professional
Richard S. Cooper. Esq., Member, McDonald Hopkins LLC

U.S. Office for Civil Rights to step up investigations of small HIPAA breaches



By Richard S. Cooper, Esq.
Member
McDonald Hopkins LLC


See all this Month's Articles

Original Publish Date: September 13, 2016

In mid-August 2016, the U.S. Department of Health and Human Services Office for Civil Rights (OCR) announced its new initiative to investigate breaches of protected health information (PHI) affecting fewer than 500 individuals.

Breaches affecting fewer than 500 individuals are sometimes referred to as “small” breaches in light of the different treatment they receive under the HITECH Act and Breach Notification Rule. Breaches involving 500 or more individuals trigger earlier OCR reporting deadlines, and are publicly disclosed on OCR’s website. Most significantly, OCR investigates all breaches involving 500 or more individuals. In contrast, breaches involving fewer than 500 individuals typically escape public disclosure and scrutiny by OCR, which investigates smaller breaches only as resources permit.

Even with OCR’s traditional focus on breaches involving at least 500 individuals, OCR has publicly disclosed at least five settlements in recent years arising out of investigations involving PHI of fewer than 500 individuals. One of these was the first HIPAA resolution agreement with a business associate, which was announced less than two months ago and provided for a $650,000 settlement payment even though only 412 patients were affected by the breach.

As a result of this change, small breaches will be less likely to slip under the radar. The change will also ratchet up the potential exposure facing HIPAA covered entities and business associates. It is therefore becoming even more important for every covered entity or business associate to maintain robust safeguards to protect the privacy and security of PHI. The following steps are particularly important:

For more information, contact the attorney below or another member our Data Privacy and Cybersecurity or Healthcare team.

Mr. Cooper provides legal representation to a broad range of hospitals, other healthcare facilities and physician groups across the United States. He has been listed in The Best Lawyers in America for health law for twenty-three consecutive years and selected for inclusion in Ohio Super Lawyers (2005-2015).

Visit the McDonald Hopkins LLC web site at www.mcdonaldhopkins.com.